Skip to content

Overview

Enterprise roles & permissions

A role is a named set of permissions. You compose the roles your enterprise needs, then assign them to members.

Note

Enterprise roles do not currently pass down permissions to sub-organisations, but this is planned for a future release. For now, roles are purely used to manage your enterprise itself.

  1. Open Roles tab in your enterprise.

  2. Select 'Create role'.

  3. Enter a Name, for example Engineering.

  4. Enter a Description, which identifies what a role does and who is assigned to it without reading the permissions.

  5. Select the Permissions the role grants.

  6. Select 'Create role' to finish creating the role.

A role grants nothing until it holds at least one permission, so an empty role cannot be saved. You can always go back and edit a role at any time after creating it.

The role editor lists the permissions your enterprise can grant, grouped by the area each one applies to. Read the editor for the current list, and use the table below to plan.

AreaPermissionsWhat they cover
MembersRead, add, update, removeSeeing the member list, inviting people, changing the roles a member holds, and ending a membership.
RolesRead, create, update, deleteSeeing roles, and composing or removing them.
DomainsRead, create, verify, deleteSeeing domains, adding one, verifying ownership, and removing one.
Single sign-onRead, create, update, delete, route domains, set applicationsSeeing connections, adding or removing one, choosing which domains route to it, and choosing which applications it may be used with.
SettingsUpdateChanging the display name and the branding.

Permission to read an area and permission to change it are granted separately. A role can therefore let someone audit single sign-on without letting them alter a connection.

By default, every enterprise comes with an owner role which grants all permissions that is not shown in the roles list and cannot be modified or removed. Only one owner can be assigned at a given time, however, you can transfer ownership to a different member by using the dots menu in the member list.

Was this page helpful?